Skip to content
View cristiancmoises's full-sized avatar
🎯
⎎⍜⌰⌰⍜⍙ ⏁⊑⟒ ⍙⊑⟟⏁⟒ ⍀⏃⏚⏚⟟⏁.
🎯
⎎⍜⌰⌰⍜⍙ ⏁⊑⟒ ⍙⊑⟟⏁⟒ ⍀⏃⏚⏚⟟⏁.

Organizations

@TheSecurityOps

Block or report cristiancmoises

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cristiancmoises/README.md

SECURITY OPS // SOVEREIGN SOFTWARE LAB

Cristian Cezar Moises

I build software that can be inspected, reproduced, self-hosted and owned.

privacy engineering · systems · GNU Guix · post-quantum experiments · free software


01 · LAUNCHPAD 02 · SYSTEMS 03 · UPSTREAM 04 · OPERATOR


Most software asks you to trust it. I prefer systems that give you evidence.

I am an IT Support Analyst from Brazil and an independent open-source builder. Outside work, I design privacy-conscious tools, experiment with secure systems, maintain self-hosted infrastructure and contribute fixes upstream.

▸ boot.log — open operator profile
operator   Cristian Cezar Moises
base       Brazil
mission    user-controlled, auditable software
runtime    GNU/Linux · GNU Guix · self-hosted infrastructure
signal     privacy · reproducibility · security · open development
status     building in public

Security claims should be testable. Infrastructure should be reproducible. Users should remain in control.

Launchpad

NODE 01 // PUBLIC INTERFACES

Live tools you can open now. Each node links back to its source.

Node What it does Source Pulse
ZUPT Encrypted backup and compression with post-quantum key encapsulation source ZUPT status
Zupt Web Post-quantum backup directly in the browser source Zupt Web status
Mirim Tiny embedded SQL database, encrypted at rest by default source Mirim status
SecurityOS Browser-based security, privacy and education environment source SecurityOS status
MusicMagic Local-first music creation studio source MusicMagic status
Dopamine Prediction-market simulator for learning — no real money source Dopamine status
TurboRec High-quality recording workflow powered by FFmpeg source TurboRec status
WhatsAppel Emacs client with a Node/Baileys bridge source WhatsAppel status

Status badges are live checks, not uptime guarantees.

Systems I build

NODE 02 // ORIGINAL SOURCE

A focused selection of original public work. Forks are intentionally excluded.

System Core idea Built with
ZUPT Authenticated encrypted backups with compression and post-quantum key encapsulation C
VaptVupt Codec Lossless LZ + tANS compression codec C
libvuptsdk Hybrid ML-KEM-768 + X25519 cryptography SDK C
Mirim Small embedded SQL with encrypted storage and sealed exports Rust
Evelin Post-quantum secure transport protocol (GitHub mirror) Rust
Cofre Soberano PQ Post-quantum signed audit logs and authenticated gateway Rust
Esquema Rootless Linux containers described as Scheme values Guile + C
SecurityOps OS Hardened GNU Guix system work Shell
GuixVis Interactive GNU Guix package and dependency explorer Rust
Guix Vault Guix-native reproducible backup and disaster recovery Scheme
Xmonad-Wayland XMonad window-management policy for the River compositor Python
Torando Per-user Tor routing with a transparent proxy and killswitch Python
Keywave Ephemeral chat and video communication without server-side storage Python
▸ inspect another layer — infrastructure and experiments
Repository Signal
securityops-channel Custom GNU Guix channel
hnews Fast, script-free Hacker News reader

Upstream traces

NODE 03 // MERGED CONTRIBUTIONS

These are external repositories I contributed to — listed separately from my own projects and backed by merged pull requests.

cabelo/libzupt — cryptographic hardening, key handling and release engineering
SciPhi-AI/R2R — service and CLI robustness
zen-browser/desktop — build configuration and scripts
Ahwxorg/Binternet — safer output handling
emmabostian/developer-portfolios — community directory

Operator console

NODE 04 // STACK AND PRINCIPLES

▸ toolchain

Systems: GNU/Linux · GNU Guix · Gentoo · FreeBSD

Languages: C · Rust · Scheme/Guile · Python · Shell · JavaScript

Operations: self-hosting · Forgejo · Docker · Tor · FFmpeg

Current orbit: reproducible systems, encrypted storage, compression, post-quantum migration and user-controlled infrastructure.

▸ operating principles
  1. Prefer evidence over security theatre.
  2. Make the source inspectable and the limits explicit.
  3. Keep infrastructure reproducible whenever practical.
  4. Design for user autonomy, not user lock-in.
  5. Learn in public and send useful fixes upstream.
▸ verified credentials — open gallery
Verified Credly credential Verified Credly credential Verified Credly credential Verified Credly credential Verified Credly credential Verified Credly credential Verified Credly credential Verified Credly credential

Open a channel

GitHub Forgejo Codeberg LinkedIn Email



if trust > evidence: inspect(source)

Security Ops® · free software · sovereign infrastructure

Pinned Loading

  1. zupt zupt Public

    Backup compression with AES-256 authenticated encryption and post-quantum key encapsulation.

    C 14 1

  2. zen-browser/desktop zen-browser/desktop Public

    Welcome to a calmer internet

    C++ 44.7k 1.8k

  3. SciPhi-AI/R2R SciPhi-AI/R2R Public

    SoTA production-ready AI retrieval system. Agentic Retrieval-Augmented Generation (RAG) with a RESTful API.

    Python 8k 651

  4. keywave keywave Public

    Secure, ephemeral chat + video communication with no server‑side storage.

    Python 3 1

  5. torando torando Public

    Tor VPN

    Python 32 3

  6. aden-hive/hive aden-hive/hive Public

    Multi-Agent Harness for Production AI

    Python 11.1k 5.7k